Skip to content

Commit 921a7ac

Browse files
Changbin Durostedt
authored andcommitted
tracing: Detect the string nul character when parsing user input string
User space can pass in a C nul character '\0' along with its input. The function trace_get_user() will try to process it as a normal character, and that will fail to parse. open("/sys/kernel/debug/tracing//set_ftrace_pid", O_WRONLY|O_TRUNC) = 3 write(3, " \0", 2) = -1 EINVAL (Invalid argument) while parse can handle spaces, so below works. $ echo "" > set_ftrace_pid $ echo " " > set_ftrace_pid $ echo -n " " > set_ftrace_pid Have the parser stop on '\0' and cease any further parsing. Only process the characters up to the nul '\0' character and do not process it. Link: http://lkml.kernel.org/r/1516093350-12045-2-git-send-email-changbin.du@intel.com Acked-by: Namhyung Kim <namhyung@kernel.org> Signed-off-by: Changbin Du <changbin.du@intel.com> Signed-off-by: Steven Rostedt (VMware) <rostedt@goodmis.org>
1 parent 2ee5b92 commit 921a7ac

File tree

1 file changed

+3
-3
lines changed

1 file changed

+3
-3
lines changed

kernel/trace/trace.c

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1237,7 +1237,7 @@ int trace_get_user(struct trace_parser *parser, const char __user *ubuf,
12371237
}
12381238

12391239
/* only spaces were written */
1240-
if (isspace(ch)) {
1240+
if (isspace(ch) || !ch) {
12411241
*ppos += read;
12421242
ret = read;
12431243
goto out;
@@ -1247,7 +1247,7 @@ int trace_get_user(struct trace_parser *parser, const char __user *ubuf,
12471247
}
12481248

12491249
/* read the non-space input */
1250-
while (cnt && !isspace(ch)) {
1250+
while (cnt && !isspace(ch) && ch) {
12511251
if (parser->idx < parser->size - 1)
12521252
parser->buffer[parser->idx++] = ch;
12531253
else {
@@ -1262,7 +1262,7 @@ int trace_get_user(struct trace_parser *parser, const char __user *ubuf,
12621262
}
12631263

12641264
/* We either got finished input or we have to wait for another call. */
1265-
if (isspace(ch)) {
1265+
if (isspace(ch) || !ch) {
12661266
parser->buffer[parser->idx] = 0;
12671267
parser->cont = false;
12681268
} else if (parser->idx < parser->size - 1) {

0 commit comments

Comments
 (0)